SecretSource.Value should be plain text in memory

This commit is contained in:
Joel Speed
2020-12-01 08:56:46 +00:00
parent d587030019
commit 5b003a5657
9 changed files with 20 additions and 52 deletions
+1 -10
View File
@@ -1,7 +1,6 @@
package validation
import (
"encoding/base64"
"fmt"
"os"
@@ -13,7 +12,7 @@ const multipleValuesForSecretSource = "multiple values specified for secret sour
func validateSecretSource(source options.SecretSource) string {
switch {
case len(source.Value) > 0 && source.FromEnv == "" && source.FromFile == "":
return validateSecretSourceValue(source.Value)
return ""
case len(source.Value) == 0 && source.FromEnv != "" && source.FromFile == "":
return validateSecretSourceEnv(source.FromEnv)
case len(source.Value) == 0 && source.FromEnv == "" && source.FromFile != "":
@@ -23,14 +22,6 @@ func validateSecretSource(source options.SecretSource) string {
}
}
func validateSecretSourceValue(value []byte) string {
dst := make([]byte, len(value))
if _, err := base64.StdEncoding.Decode(dst, value); err != nil {
return fmt.Sprintf("error decoding secret value: %v", err)
}
return ""
}
func validateSecretSourceEnv(key string) string {
if value := os.Getenv(key); value == "" {
return fmt.Sprintf("error loading secret from environent: no value for for key %q", key)